When monit requires authentication, but the browser fails to provide credentials, a rather useless message (401 You are not authorized to access monit) is written to syslog (each time the browser makes an attempt). Either "You" has to be replaced by useful information (like network address and port), or the message should to be logged at all. If logged, there should be a rate or count limit to avoid flooding the syslog.

    • log client IP address for failed HTTP requests
    • log authentication error details for internal use instead of the generic message sent to user

